In Palo Alto Networks K2-Series, there is a Zero Trust segmentation feature that I worked with. It is straightforward to plug that with Palo Alto CIE, Cloud Identity Engine, and then build. For Palo Alto, it's all about security policies that you configure with User-ID and App-ID based policies. We had configured dynamic user groups and App-ID based policies, which makes it all Zero Trust. Regarding traffic visibility features and Advanced Threat Prevention aspects, I would assess these functions as awesome. It's unparalleled, not just for K2-Series, but in general for Palo Alto. These features are state of art with little comparison from other vendors. We had activated antivirus, anti-spyware, threat prevention, and elaborate custom signatures on threat prevention depending on client requirements. Additionally, there was DNS Security, Advanced URL Filtering, and WildFire for sandboxing.